logo

MBS Universal Gateway Flaws Threaten Building Automation Networks

ID: 6b9f6668-afcd-5d5c-89bf-5e14788ece32

STIX ID: report--6b9f6668-afcd-5d5c-89bf-5e14788ece32

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Do Son

...
...

Multiple critical vulnerabilities were disclosed in MBS Universal Gateway firmware (V6_0_0_5 and earlier), including a hard-coded default password (CVE-2026-35075, CVSS 9.8) enabling unauthenticated full administrative access; three stack buffer overflow flaws (CVE-2026-35085/35084/35083, CVSS 8.8) that can lead to remote root compromise and path traversal; and input-validation/CGI bugs allowing arbitrary file deletion. Administrators are advised to immediately update affected devices to firmware V6_0_0_7 and monitor configuration files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.